Skip to content

fix(scan): record baselined findings in scan output - #338

Closed
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/baseline-suppression-audit-8f48
Closed

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/baseline-suppression-audit-8f48

Conversation

@vibgrate-team

Copy link
Copy Markdown
Contributor

Summary

vg scan --baseline compared a saved baseline only to compute a numeric drift delta (and to drive --drift-worsening). Matched findings were not recorded anywhere in the machine-readable artifact, so a baseline looked like a silent drop.

The scan artifact now keeps every finding in findings and adds an auditable baselineComparison block when a baseline file is read:

"baseline": ".vibgrate/baseline.json",
"delta": 2,
"baselineComparison": {
  "compared": true,
  "suppressedCount": 2,
  "suppressed": [
    { "ruleId": "vibgrate/dependency-rot", "location": "package.json", "id": "…" }
  ]
}
  • suppressed is sorted by ruleId, then location, then id.
  • id is 32 lowercase hex characters from the finding's rule, level, location, and message. The same finding always produces the same id; a changed message does not match.
  • The existing baseline string (the compared file path) is unchanged, so the schema addition is version-safe. The comparison record is the new object rather than a replacement for that string.
  • Text and Markdown reports include Baseline suppressions: N and mark matched rows (baselined).
  • SARIF keeps those results and adds a suppressions entry whose properties.id is the same id. Unmatched results have no suppressions field.

Related issues

Fixes #161

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical graph.json / report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

Verify with the fixture in test/fixtures/baseline-suppressions.json (no credentials) and:

pnpm exec vitest run test/baseline-comparison.test.ts src/reporting/formatters/formatters.test.ts
vg baseline
vg scan --baseline .vibgrate/baseline.json --format json

The JSON artifact should contain baselineComparison alongside the full findings array. --format sarif should repeat those ids under suppressions, and the text report should include the count.

Open in Web Open in Cursor 

vg scan --baseline previously kept only a numeric drift delta, so matched
findings left no auditable trace in JSON or SARIF. The artifact now includes
baselineComparison (compared, suppressedCount, and suppressed sorted by
ruleId, location, then id). Findings stay in the primary array, human
reports include the count, and SARIF suppressions carry the same ids.

Fixes #161

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Baseline/suppressions: leave an auditable trace in machine-readable scan output

2 participants